Remix.run Logo
▲ TemplarRush 3 hours ago

They aren't hard to generate. They give you how to generate them via their own documentation. It's just made up of an app ID, service type code, mailer ID, serial number, and check digit.

▲devy 2 hours ago | parent [-]

No. That won't work. Every carrier has it own way to generate tracking number. And that number must have registered in the carrier's database before it becomes "valid/sanctioned".

If you generate a random number even fitting the pattern and looks like a real one, the scan will fail with an error and fail to register tracking information every single step of the way that package gets scanned from dropoff at the retail postal office (this was the case) as bulk inbound pickup from USPS are only allowed for USPS verified partners.

Label creation (which generates the tracking number) is a billable action in their API. Some volume partners have pre-arranged/allocated tracking number segments assigned to the bulk volume partner/shipper (similar like how IP address v4 is assignment from IANA). And that pre-allocation tracking number range requires $$$$ contract in place. Billing that is post paid like cellphone bill.

Most retail shipping software (like shipengine, pirateship etc.) bills using the prepaid method, meaning you will have to pay for the label at the time label is generated.

Disclaimer: I used to work for a carrier that integrated a few dozens of global shipping carriers.

▲theturtletalks 2 hours ago | parent | next [-]

Yes, I’m deep in e-commerce and fraudulent labels are all over the place. Even Amazon, 3rd party sellers are using these fake labels to sell items for cheaper and win the buy box. Even UPS has this issue.

I get that they have reverse engineered how the numbers are created, but how are they showing up in USPS and UPS databases?

Are shipping platforms like shipengine getting these labels pre-made and this fake label seller has reverse engineered how these tracking numbers are created programmatically and are essentially using the ones allocated to these big shipping platforms?

▲devy an hour ago | parent | next [-]

And the only plausible way they got around is likely recycle previously used real tracking numbers because USPS is inept (the thing USPS has been constant and consistent is raising prices).

We would never know how since that's the part USPS redacted heavily.

I wish Anthropic/OpenAI FDE take over USPS IT altogether.

▲mmooss an hour ago | parent | prev [-]

> how are they showing up in USPS and UPS databases?

Are you overestimating their validation capabilities? Maybe the validation just isn't that accurate or isn't always done, for efficiency.

I once desperately needed a (FedEx or UPS) package that was delayed. Tracking showed it in a facility about an hour away so I asked if I could pick it up there. I was told: 'It's not really there; our (customer-facing) tracking shows where packages should be.'

Their image of super-efficiency is for selling themselves. (If you are deep in e-commerce, you probably already know.)

▲theturtletalks 8 minutes ago | parent [-]

Yeah USPS definitely reuses tracking numbers, but how were these guys able to overwrite the delivery address? I feel like this shouldn’t be possible unless they are inside the system.

▲TemplarRush an hour ago | parent | prev [-]

Correct, I was just pointing out how trivial it was to generate/counterfeit a USPS barcode. I also worked in shipping/logistics with heavy USPS integration, but it was dealing with bulk/volume labels, where we'd only get charged if the label was actually used (returns, etc).